Strictly necessary cookies
They are required for the requested service, authentication, and security. Disabling them may prevent sign-in, form protection, and account features. All are first-party, HttpOnly and Secure in production, with SameSite=Lax.
unimatch_sessionKeeps the user signed in and references a protected server-side session.
Up to 7 days; up to 12 hours for administrators.
unimatch_csrfProtects authenticated actions against cross-site request forgery (CSRF).
For the browser session.
unimatch_oauthProtects and completes a Google sign-in or account-linking attempt.
Up to 10 minutes, restricted to the callback path.
Local storage
These values remain in the browser and are not cookies. Tab route preferences may also remain in sessionStorage only until the tab session ends.
unimatch.languageRemembers the selected language.
Until removed by the user.
themeRemembers the selected visual theme.
Until removed by the user.
university-match:favoritesKeeps local favorites while account-synced data is being adopted.
Until removed or replaced by synchronization.
universitymatch.cookie-notice.v1Records only that this notice was read; it does not enable tracking.
Until removed by the user or replaced by a new version.
Google and third parties
When selecting Google sign-in, you are redirected to Google, which may use its own cookies under its policy. UniversityMatch cannot read those cookies. We currently embed no advertising pixels or third-party cookies.
How to control
You can delete cookies and local data in browser settings. This signs you out and resets preferences. If optional cookies are added, they will remain disabled until the applicable choice and this policy will be updated.
More information
See the Privacy Policy or contact our privacy channel.